vom-HF050001960-25
Obsolete
The latest patch(es) : vom-HF050001960-35 

 Basic information
Release type: Hot Fix
Release date: 2013-03-21
OS update support: None
Technote: None
Documentation: None
Popularity: 759 viewed    downloaded
Download size: 14.59 KB
Checksum: 3758530942

 Applies to one or more of the following products:
Operations Manager 5.0 On Linux
Operations Manager 5.0 On Solaris 10 SPARC
Operations Manager 5.0 On Windows

 Obsolete patches, incompatibilities, superseded patches, or other requirements:

This patch is obsolete. It is superseded by: Release date
vom-HF050001960-35 2013-07-30

 Fixes the following incidents:
3117726

 Patch ID:
None.

Readme file
                          * * * READ ME * * *
               * * * Veritas Operations Manager 5.0 * * *
                          * * * Hot Fix * * *
                         Patch Date: 2013-03-14


This document provides the following information:

   * PATCH NAME
   * OPERATING SYSTEMS SUPPORTED BY THE PATCH
   * PACKAGES AFFECTED BY THE PATCH
   * BASE PRODUCT VERSIONS FOR THE PATCH
   * SUMMARY OF INCIDENTS FIXED BY THE PATCH
   * DETAILS OF INCIDENTS FIXED BY THE PATCH
   * INSTALLATION PRE-REQUISITES
   * INSTALLING THE PATCH
   * REMOVING THE PATCH


PATCH NAME
----------
Veritas Operations Manager 5.0 Hot Fix


OPERATING SYSTEMS SUPPORTED BY THE PATCH
----------------------------------------
RHEL5 x86-64
SLES10 x86-64
RHEL6 x86-64
Solaris 10 SPARC
Windows 2003 X64
Windows 2008 X64
Windows Server 2008 R2 X64



BASE PRODUCT VERSIONS FOR THE PATCH
-----------------------------------
   * Veritas Operations Manager 5.0


SUMMARY OF INCIDENTS FIXED BY THE PATCH
---------------------------------------
Patch ID: HF050001960-25
* 3117726 (3101454) Arbitrary File Read as ROOT


DETAILS OF INCIDENTS FIXED BY THE PATCH
---------------------------------------
This patch fixes the following Symantec incidents:

Patch ID: HF050001960-25

* 3117726 (Tracking ID: 3101454)

SYMPTOM:
A logged in user can change the URL input parameters for archived reports.

DESCRIPTION:
This hotfix provides enhanced validation of user inputs, and discards requests 
with invalid parameter values.

RESOLUTION:
Enhanced validation of request parameters in  URL.



INSTALLING THE PATCH
--------------------
This hotfix is applicable for VOM 5.0 Management Server.

1. Download the file HF050001960-25.sfa
2. Launch a browser and login to the VOM management server.
3. Navigate to Settings ->      Deployment Management tab.
4. Upload the add-on to the VOM CMS using the "upload" button.
   The HF HF050001960-25 should be visible in the table below.
5. HF install instructions
    - In the Deployment Management page,  click on the HF HF050001960-25 and it will take you to the Deployment Summary page. Select the 5.0 Management server on which you want to apply the HF and click on the Install button.


REMOVING THE PATCH
------------------
1. Launch a browser and login to the VOM management server.
2. Navigate to Settings ->      Deployment Management tab.
3. Remove instruction for HF
   - In the Deployment Management page, click on the HF HF050001960-25 and it will take you to the Deployment Summary page. Select the 5.0  management server on which the status shown is "Enabled" (HF installed) and click on Uninstall button.


SPECIAL INSTRUCTIONS
--------------------
NONE


OTHERS
------
NONE